typecho records
18 published records for vendor typecho.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-290 Authentication Bypass by Spoofing2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-776 Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')1
- CWE-912 Hidden Functionality1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-18753No exploit | Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.typecho · typecho · CWE-918 | Critical9.8 | — | 3.5% | Oct 29, 2018 |
39Monitor | CVE-2023-24114No exploit | typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.typecho · typecho · CWE-94 | Critical9.8 | — | 1.4% | Feb 22, 2023 |
37Monitor | CVE-2024-35540Proof of concept | A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted typecho · typecho · CWE-79 | Critical9.0 | — | 2.8% | Aug 20, 2024 |
36Monitor | CVE-2023-36299No exploit | A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general paramettypecho · typecho · CWE-434 | High8.8 | — | 1.8% | Aug 3, 2023 |
30Monitor | CVE-2023-49967No exploit | Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.typecho · typecho · CWE-776 | High7.5 | — | 0.7% | Dec 7, 2023 |
26Monitor | CVE-2024-35539Proof of concept | Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function.typecho · typecho · CWE-290 | Medium6.5 | — | 1.4% | Aug 19, 2024 |
25Monitor | CVE-2024-57369No exploit | Clickjacking vulnerability in typecho v1.2.1.typecho · typecho · CWE-1021 | Medium6.4 | — | 0.4% | Jan 17, 2025 |
24Monitor | CVE-2020-21038No exploit | Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.typecho · typecho · CWE-601 | Medium6.1 | — | 0.5% | May 8, 2023 |
21Monitor | CVE-2023-6615No exploit | Typecho manage-users.php information disclosuretypecho · typecho · CWE-200 | Medium5.3 | — | 0.7% | Dec 8, 2023 |
21Monitor | CVE-2024-35538Proof of concept | Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifytypecho · typecho · CWE-290 | Medium5.3 | — | 0.6% | Aug 19, 2024 |
21Monitor | CVE-2017-16230No exploit | In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article ctypecho · typecho · CWE-79 | Medium5.4 | — | 0.5% | Oct 30, 2017 |
21Monitor | CVE-2023-30184No exploit | A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted typecho · typecho · CWE-79 | Medium5.4 | — | 0.4% | May 4, 2023 |
21Monitor | CVE-2024-46494No exploit | A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payloadtypecho · typecho · CWE-79 | Medium5.4 | — | 0.3% | Apr 7, 2025 |
19Monitor | CVE-2023-27711No exploit | Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admitypecho · typecho · CWE-79 | Medium4.8 | — | 0.7% | Mar 16, 2023 |
19Monitor | CVE-2023-27131No exploit | Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code viathe Post Editorparameter.typecho · typecho · CWE-79 | Medium4.8 | — | 0.6% | Mar 16, 2023 |
19Monitor | CVE-2023-27130No exploit | Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an arbitrarily supplied Utypecho · typecho · CWE-79 | Medium4.8 | — | 0.6% | Mar 16, 2023 |
19Monitor | CVE-2023-6613No exploit | Typecho Logo options-theme.php cross site scriptingtypecho · typecho · CWE-79 | Medium4.8 | — | 0.6% | Dec 8, 2023 |
10Monitor | CVE-2023-6614No exploit | Typecho Page manage-pages.php backdoortypecho · typecho · CWE-912 | Low2.7 | — | 0.6% | Dec 8, 2023 |
- CVE-2018-1875340Plan
Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.
CriticalCVSS 9.8No exploitEPSS 3%typecho · typechoOct 29, 2018
- CVE-2023-2411439Monitor
typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.
CriticalCVSS 9.8No exploitEPSS 1%typecho · typechoFeb 22, 2023
- CVE-2024-3554037Monitor
A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted
CriticalCVSS 9.0Proof of conceptEPSS 3%typecho · typechoAug 20, 2024
- CVE-2023-3629936Monitor
A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general paramet
HighCVSS 8.8No exploitEPSS 2%typecho · typechoAug 3, 2023
- CVE-2023-4996730Monitor
Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.
HighCVSS 7.5No exploitEPSS 1%typecho · typechoDec 7, 2023
- CVE-2024-3553926Monitor
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function.
MediumCVSS 6.5Proof of conceptEPSS 1%typecho · typechoAug 19, 2024
- CVE-2024-5736925Monitor
Clickjacking vulnerability in typecho v1.2.1.
MediumCVSS 6.4No exploitEPSS 0%typecho · typechoJan 17, 2025
- CVE-2020-2103824Monitor
Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.
MediumCVSS 6.1No exploitEPSS 0%typecho · typechoMay 8, 2023
- CVE-2023-661521Monitor
Typecho manage-users.php information disclosure
MediumCVSS 5.3No exploitEPSS 1%typecho · typechoDec 8, 2023
- CVE-2024-3553821Monitor
Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specify
MediumCVSS 5.3Proof of conceptEPSS 1%typecho · typechoAug 19, 2024
- CVE-2017-1623021Monitor
In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article c
MediumCVSS 5.4No exploitEPSS 1%typecho · typechoOct 30, 2017
- CVE-2023-3018421Monitor
A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted
MediumCVSS 5.4No exploitEPSS 0%typecho · typechoMay 4, 2023
- CVE-2024-4649421Monitor
A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload
MediumCVSS 5.4No exploitEPSS 0%typecho · typechoApr 7, 2025
- CVE-2023-2771119Monitor
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admi
MediumCVSS 4.8No exploitEPSS 1%typecho · typechoMar 16, 2023
- CVE-2023-2713119Monitor
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code viathe Post Editorparameter.
MediumCVSS 4.8No exploitEPSS 1%typecho · typechoMar 16, 2023
- CVE-2023-2713019Monitor
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an arbitrarily supplied U
MediumCVSS 4.8No exploitEPSS 1%typecho · typechoMar 16, 2023
- CVE-2023-661319Monitor
Typecho Logo options-theme.php cross site scripting
MediumCVSS 4.8No exploitEPSS 1%typecho · typechoDec 8, 2023
- CVE-2023-661410Monitor
Typecho Page manage-pages.php backdoor
LowCVSS 2.7No exploitEPSS 1%typecho · typechoDec 8, 2023